Videmora

Videmora

Privacy Policy

Effective date: [DATE ON PUBLISH] · Version 3.0 — International

Plain-language summary (not a substitute for the full policy below): You upload family photos and videos. We use AI technology to analyze them, match faces across your own photos so names get attached to the right person, write a story, generate narration, and render a video. We never sell your personal information or biometric data. You can request deletion of your account and everything tied to it at any time.

If you're in…The law that primarily appliesJump to
United StatesState privacy laws (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA), BIPA/CUBI/WA biometric laws, COPPASection 12
United KingdomUK GDPR & the Data Protection Act 2018Section 13
European Union / EEAEU General Data Protection Regulation (GDPR)Section 13
CanadaPIPEDA (federal), Quebec's Law 25 where applicableSection 14
AustraliaPrivacy Act 1988 & the Australian Privacy PrinciplesSection 15
Anywhere elseThe general protections in Sections 1–11 & 17–22 apply to you regardlessSection 16

01Who we are & scope of this policy

Videmora, Inc., a Delaware corporation ([registered address on formation]), founded by Md. Robiul Alam and Joy Das ("Videmora," "Company," "we," "us," or "our"), operates the Videmora website, application, and related services (collectively, the "Service"). This Privacy Policy describes how we collect, use, disclose, and safeguard personal information when you use the Service, and the rights available to you depending on where you live. Our primary markets are the United States, United Kingdom, Australia, and Canada, so Sections 12–15 address those jurisdictions specifically; Section 16 covers everyone else.

This Policy applies to all visitors, registered users, and other individuals who access the Service ("you," "user"). It does not apply to third-party websites, products, or services linked to or integrated with the Service, which are governed by their own privacy policies.

If you do not agree with this Policy, please discontinue use of the Service.

02Definitions

  • "Personal Information" / "Personal Data" means information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with an identified or identifiable individual — this Policy uses "Personal Information" throughout to mean both terms interchangeably, matching whichever term the law of your jurisdiction uses.
  • "Biometric Identifier" / "Biometric Information" means a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry, and any information based on such an identifier used to identify an individual — this includes "special category data" and "sensitive information" as those terms are used under GDPR and the Australian Privacy Act, respectively.
  • "Content" means any photo, video, text, or other material you upload to, or generate through, the Service.
  • "Service Provider" / "Processor" means a third party that processes Personal Information on our behalf and under our instructions.
  • "Controller" (EU/UK terminology) means the entity that determines the purposes and means of processing Personal Information — Videmora acts as the Controller for the Personal Information described in this Policy.

03Information we collect

3.1 Information you provide directly

CategoryExamples
Account & identity dataName, email address, authentication credentials (password stored as a salted cryptographic hash, never in plaintext)
Uploaded ContentPhotos and videos you upload, and embedded file metadata (timestamp, device model, GPS coordinates if present)
People & relationship dataNames and relationship labels you assign to individuals appearing in your Content
Payment & billing dataHandled by our third-party payment processor once payment processing is live; Videmora does not receive or store full payment card numbers. [payment processing not yet active as of this version — this Policy will be updated with the specific processor's name before checkout goes live]
CommunicationsSupport requests, survey responses, correspondence you send us

3.2 Information collected automatically

CategoryExamples
Device & usage dataIP address, browser type/version, operating system, device identifiers, referring URLs, pages viewed, timestamps
Cookies & similar technologiesSee our separate Cookie Policy
Diagnostic & error dataCrash logs, performance metrics, error reports

3.3 Information generated through AI processing of your Content

CategoryExamples
Derived scene/content analysisAI-generated descriptions of scenes, objects, estimated emotional tone
Facial detection dataBounding-box coordinates identifying where faces appear within an image
Biometric matching dataSee Section 7 — treated as sensitive Personal Information under this Policy and applicable law everywhere we operate
Generated OutputAI-written narrative text, synthesized narration audio, rendered video files

04Legal bases for processing (relevant to UK/EU users, and good practice everywhere)

Where UK GDPR or EU GDPR applies to you, we rely on the following legal bases to process your Personal Information:

  • Performance of a contract — processing your uploaded Content to generate your memory film, since that's the service you've asked us to perform.
  • Consent — for biometric facial-matching (Section 7) and for non-essential cookies (see our Cookie Policy), both of which require your affirmative opt-in under GDPR's treatment of special category data and the UK's Privacy and Electronic Communications Regulations (PECR). You may withdraw consent at any time, as described in Sections 7 and 17, without affecting the lawfulness of processing carried out before withdrawal.
  • Legitimate interests — for security, fraud prevention, and service improvement, balanced against your rights and only where our interest is not overridden by your interests or fundamental rights.
  • Legal obligation — where we must retain or disclose information to comply with applicable law (e.g., tax recordkeeping, responding to lawful requests from authorities).

05AI processing & automated decision-making

The Service relies substantially on artificial intelligence technology, including image analysis technology, large language model text-generation technology, voice synthesis technology, and biometric facial-matching technology. This processing is automated: no human reviews your Content as a routine part of providing the Service, other than automated moderation and, where necessary, limited human review to investigate abuse reports, security incidents, or legal obligations.

This automated processing determines how faces are matched within your own uploaded photos and how narrative text is generated — it does not make any decision producing a legal or similarly significant effect concerning you (it does not determine eligibility for credit, employment, housing, insurance, or similar outcomes). Under UK/EU GDPR Article 22, you have the right not to be subject to a decision based solely on automated processing that produces such effects; because our processing does not produce such effects, Article 22's core protection is not triggered, but you may still contact us under Section 17 with questions about how this processing works.

06How information is shared

We do not sell your Personal Information, anywhere. We share information only in the following circumstances:

6.1 Service providers, by functional category

Functional categoryPurposeData involved
AI image & content analysis technologyAnalyzing uploaded photosUploaded photos
AI language generation technologyGenerating narrative story textContent analysis output, names/relationships you provide
AI voice synthesis technologyGenerating spoken narrationGenerated story text
Biometric facial-matching technologyMatching the same face across photos within your own sessionUploaded photos, derived facial geometry data — see Section 7
Cloud video rendering infrastructureAssembling photos, narration, and text into a finished videoPhotos, narration audio, story text
Cloud database & file storage infrastructureStoring account, content, and application dataAll categories described in Section 3
Application hosting infrastructureServing the website and applicationAll data in transit through the Service
Payment processing partnerProcessing purchases and managing billing, once livePayment and billing details only [processor to be named here once integrated]

We describe most service providers by functional category rather than naming specific commercial vendors in this public-facing document, to avoid giving competitors a roadmap to our technology stack. A complete list of current sub-processors, including specific vendor names and, where applicable, their Standard Contractual Clauses or other transfer safeguards, is available upon written request to the contact in Section 22, and will be provided to any user or regulator entitled to it under applicable law.

6.2 Legal & safety disclosures

We may disclose information where required to comply with valid legal process, to enforce our Terms of Service, to detect or prevent fraud or security incidents, to protect the rights, property, or safety of Videmora, our users, or the public, or in connection with a merger, acquisition, financing, or sale of assets (requiring the successor to honor the commitments in this Policy).

6.3 With your direction

When you generate a shareable link, the story text and video become accessible to anyone with the link, until you disable sharing.

07Biometric information

The Service uses biometric facial-matching technology to detect faces in your uploaded photos and generate a mathematical representation of facial geometry (a "faceprint") so the same person can be recognized and consistently named across multiple photos within your own session. This is regulated as sensitive/special-category data under multiple frameworks, including the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act, Washington's biometric privacy law, UK/EU GDPR Article 9 (special category data — biometric data used for the purpose of uniquely identifying a natural person), and the Australian Privacy Act's treatment of biometric information as "sensitive information" under Australian Privacy Principle 3.

Our written biometric data policy

Purpose: collected solely to provide the in-session face-matching feature described above.

No sale or profit: we do not sell, lease, trade, or otherwise profit from biometric identifiers, and we do not disclose biometric data to any party other than the processor strictly necessary to provide the feature, except where required by valid legal process.

Retention: we permanently destroy biometric identifiers when the initial purpose has been satisfied, or within three (3) years of your last interaction with the Service, whichever is first. On a verified account deletion request, we remove associated facial-matching records from the underlying biometric matching system, not merely from our own database.

Legal basis / consent: where GDPR applies, we rely on your explicit consent (GDPR Art. 9(2)(a)) for this processing, given through your acceptance of this Policy and your affirmative act of using the naming/tagging feature; where BIPA and similar US laws apply, this constitutes the informed written consent those statutes require. In every jurisdiction, you may withdraw consent at any time by discontinuing use of the naming feature and requesting deletion under Section 17 — this will not affect processing already lawfully carried out.

08Information about people who aren't account holders

Family photographs routinely include people who have never created a Videmora account. When you upload a photo, you represent and warrant that you possess the necessary rights and consent — including, where a depicted individual is a minor, consent from that minor's parent or legal guardian — to have that photo processed as described in this Policy, including biometric facial-matching under Section 7. You, the uploading account holder, are solely responsible for obtaining that consent.

If you are an individual who appears in a photo uploaded by another user and wish to exercise a privacy right described in Sections 12–17 with respect to your own data, contact us at Section 22. We will process such requests in accordance with applicable law, which may require verification of your identity and relationship to the relevant account or Content.

09Children's privacy

The Service is intended for users at least 18 years old, and account registration is restricted accordingly. This is intentionally higher than the minimum age of digital consent in most of our primary markets (commonly 13–16 depending on jurisdiction) because of the sensitivity of biometric processing involved. We do not knowingly collect Personal Information directly from a child for purposes of COPPA (US), the UK's Age Appropriate Design Code, or equivalent frameworks; all account holders are adults, and all uploads are made by an adult rather than collected directly from a child.

Because Videmora is a family-memory product, Content will routinely depict minors as uploaded by a parent, legal guardian, or other authorized adult. If we become aware that data about a minor was uploaded without appropriate authorization, we will investigate and, where warranted, delete the relevant data. Parents or guardians who believe their child's information has been collected inappropriately may contact us using Section 22.

10Data retention schedule

Data categoryRetention period
Active account & Content dataRetained for as long as the account remains active
Biometric identifiersDestroyed when the purpose is satisfied, or within 3 years of your last interaction, whichever is first
Deleted account — primary systemsRemoved within 30 days of a verified deletion request
Deleted account — backupsPurged within 90 days of a verified deletion request
Billing & transaction recordsRetained independently of account deletion for 7 years, as required for tax and financial recordkeeping (once payment processing is live)
Security & fraud-prevention logsUp to 12 months, or longer to investigate an active incident
Inactive accountsWe may notify you and deactivate/delete after 24 months of continuous inactivity

11Security

We implement administrative, technical, and physical safeguards designed to protect Personal Information, including encryption in transit (TLS), encryption at rest where supported by our infrastructure providers, database-level access controls restricting each account to its own data, and restricted internal access to production systems on a need-to-know basis. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12United States

12.1 California (CCPA/CPRA)

California residents have rights to know, correct, delete, and port their Personal Information; to opt out of sale or sharing (we do not sell or share, and have not in the preceding 12 months); to limit use of sensitive Personal Information including biometric data; to opt out of certain automated-decision profiling (see Section 5); to non-discrimination for exercising these rights; and to appeal a denied request (Section 17). California residents may designate an authorized agent to submit a request, subject to our ability to verify the agent's authority.

12.2 Virginia, Colorado, Connecticut & Utah

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and Utah (UCPA) have rights to access, correct, delete, and port their Personal Information, and to opt out of targeted advertising, sale, and certain profiling. We do not engage in targeted advertising or sell Personal Information. Where these statutes grant an appeal right, see Section 17.

12.3 Illinois, Texas & Washington (biometric-specific)

See Section 7 for our written biometric data policy, applicable to residents of these states and to anyone whose biometric information we process.

12.4 Nevada

Nevada residents may direct us not to sell covered information; as stated above, we do not sell Personal Information.

13United Kingdom & European Union

If UK GDPR or EU GDPR applies to you, in addition to the rest of this Policy, you have the following rights, which you may exercise via Section 17:

  • Right of access — obtain confirmation of whether we process your data and a copy of it
  • Right to rectification — correct inaccurate or incomplete data
  • Right to erasure ("right to be forgotten") — request deletion, subject to the retention exceptions in Section 10
  • Right to restrict processing — limit how we use your data in certain circumstances
  • Right to data portability — receive your data in a structured, commonly-used, machine-readable format
  • Right to object — object to processing based on legitimate interests
  • Right to withdraw consent at any time, for processing based on consent (Sections 4 and 7), without affecting the lawfulness of prior processing
  • Right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ICO); in the EU, your local data protection authority

GDPR Art. 27 / UK GDPR Art. 27If we process personal data of individuals in the UK or EU in connection with offering the Service to them, and that processing is not merely occasional or low-risk, we may be required to appoint a UK and/or EU representative. [Founders to assess based on actual UK/EU user volume and appoint a representative if the exemption for occasional, low-risk processing does not apply; representative contact details to be added here once appointed.]

14Canada

If you're in Canada, the federal Personal Information Protection and Electronic Documents Act (PIPEDA) applies to our handling of your Personal Information, alongside applicable provincial law (for example, Quebec's Law 25, which applies additional requirements for Quebec residents including a right to data portability and rules on automated decision-making). You have the right to access and request correction of your Personal Information, to withdraw consent (subject to legal or contractual restrictions), and to file a complaint with the Office of the Privacy Commissioner of Canada (or, for Quebec residents, the Commission d'accès à l'information).

15Australia

If you're in Australia, the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply. Biometric information is "sensitive information" under APP 3, requiring your consent to collect except in limited circumstances — consistent with the consent basis described in Section 7. You have the right to access and seek correction of your Personal Information under APP 12–13, and to complain to us directly (Section 22) or, if unresolved, to the Office of the Australian Information Commissioner (OAIC). Consistent with the Notifiable Data Breaches (NDB) scheme, we will notify the OAIC and affected individuals as soon as practicable if an "eligible data breach" occurs, per Section 20.

16Other jurisdictions

If you're located somewhere not specifically addressed in Sections 12–15, the general protections described throughout this Policy — our commitment not to sell your data, our biometric data safeguards (Section 7), our retention schedule (Section 10), and our security practices (Section 11) — apply to you regardless of your location. Contact us via Section 22 with any question about how local law interacts with our practices, and we will respond in good faith even where a formal statutory right may not apply in your jurisdiction.

17How to exercise your rights & our response timeframes

  • How to submit a request: email the address in Section 22, or use the account deletion / data export tool within the Service where available.
  • Verification: we will take reasonable steps to verify your identity before acting on a request. We will not request more information than reasonably necessary for verification.
  • US response time: we confirm receipt within 10 business days and substantively respond within 45 calendar days, extendable by one additional 45-day period with notice to you.
  • UK/EU response time: we respond within one (1) month of receipt, extendable by a further two months for complex or numerous requests, with notice to you within the first month explaining the extension, consistent with GDPR Article 12.
  • Canada & Australia response time: we respond "as soon as reasonably possible," and in any case within 30 days, consistent with common practice under PIPEDA and the APPs.
  • Appeal (US state laws): if we decline a request, you may appeal within 30 days; we respond to appeals within 45 days, and if we uphold the denial, we will explain why and, where required, provide information on how to complain to the applicable regulator.
  • No fee: we do not charge a fee to process a request unless it is excessive, repetitive, or manifestly unfounded, in which case we will explain the basis for any fee before proceeding, or may refuse the request as permitted under applicable law.

18Cookies & tracking technologies

We use cookies and similar technologies as described in our separate Cookie Policy, incorporated into this Privacy Policy by reference. Where UK PECR or the EU ePrivacy framework applies, we obtain your consent before setting non-essential cookies. We honor the Global Privacy Control ("GPC") signal as a valid opt-out signal where legally required to do so.

19International data transfers

Videmora, Inc. is a Delaware corporation, and our infrastructure and service providers operate primarily in the United States. If you access the Service from the UK, EU, Canada, Australia, or elsewhere, your information will be transferred to and processed in the United States, where data protection laws differ from those of your home jurisdiction.

Where UK or EU GDPR requires a specific transfer safeguard for this to be lawful, we rely on one or more of: the European Commission's Standard Contractual Clauses (SCCs), the UK's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, or another legally recognized transfer mechanism, incorporated into our agreements with the relevant service providers. [Founders: confirm and document which specific mechanism is in place with each provider once sub-processor agreements are finalized; details available on request per Section 6.]

20Security incident notification

If we become aware of a security incident compromising the confidentiality, integrity, or availability of your Personal Information in a manner requiring notification, we will notify affected individuals and relevant regulators consistent with the specific timing required in your jurisdiction:

  • UK/EU: notification to the ICO or relevant supervisory authority without undue delay, and where feasible, within 72 hours of becoming aware, per GDPR Article 33.
  • Australia: notification to the OAIC and affected individuals "as soon as practicable" for an eligible data breach, per the Notifiable Data Breaches scheme.
  • Canada: notification to the Privacy Commissioner and affected individuals "as soon as feasible" for a breach posing a real risk of significant harm, per PIPEDA.
  • United States: notification consistent with the applicable state breach-notification statute, commonly "without unreasonable delay" up to a maximum of 30–60 days depending on the state.

21Changes to this policy

We may update this Policy to reflect changes in our practices or applicable law. We will update the effective date above, and for material changes, provide more prominent notice (such as an in-app notification or email) at least 10 days before the change takes effect where reasonably practicable. Continued use of the Service after a change takes effect constitutes acceptance.

22Contact us & representatives

Videmora, Inc., a Delaware corporation
Founders: Md. Robiul Alam, Joy Das
Registered agent for service of process (US): [registered agent name & Delaware address on formation]
UK representative (Art. 27, if applicable): [to be appointed if required — see Section 13]
EU representative (Art. 27, if applicable): [to be appointed if required — see Section 13]
Privacy inquiries: [privacy@videmora.com]
General inquiries: [hello@videmora.com]

Videmora, Inc. · This document is an AI-assisted draft template prepared for founder review and has not been reviewed by a licensed attorney. Replace all bracketed placeholders — particularly Sections 7, 13, and 19 — and obtain legal review before publishing, especially before actively marketing to UK/EU users given the Article 27 representative question.